Draft policy · 2026-01-draft
Privacy policy (draft)
Written to describe what the platform actually does today, including the parts that are incomplete.
1. Status of this document
This is a draft platform policy, version 2026-01-draft. It describes how the platform is built and currently behaves. It is not a certification, and Blue Hat Founders does not claim any regulatory authorisation, security certification or audit status.
2. What we collect
Account data: your email address, name and avatar from your chosen sign-in method, your timezone and the role you selected.
Founder data: company name, website, description, location, sectors, stage, raise target and currency, check range, instrument, traction figures split into actual and projected periods, narrative, tags, prior companies and any evidence URLs you supply.
Uploaded documents: your pitch deck and projections files, stored in a private bucket that is not publicly listable.
Investor data: firm URL and domain, firm details you confirm or enter, thesis text, entity type, jurisdiction, sectors, stages, check range, geographies, exclusions, portfolio conflicts, lead preference and deployment timing.
Activity data: matches generated for you, shortlists, passes with reasons, genuine profile opens, introduction states and in-app notifications.
3. How uploaded documents are processed
Documents are stored privately. They are never published, never listed, and never served from a public URL. When an authorised party needs to read one, our server checks permission and issues a short-lived signed link.
Where extraction is supported, document text is sent to a third-party AI model to be structured into comparable fields with page references. The model is instructed to extract only, never to invent, and to mark unknown fields as unknown.
Text inside your documents is treated strictly as content. Any instruction-like text found inside an upload is never executed.
Where extraction is not supported for a file type, we say so before you upload, store the file unprocessed, and route it to manual review rather than silently failing.
4. Third-party processing
AI structuring is performed by third-party model providers reached through our gateway. Investor firm research fetches publicly available web pages through a third-party research provider.
Research reads only public pages. It stores the source URL, fetch date and a confidence value with every field so you can judge and correct it.
5. Human correction
Every AI-produced field and every researched field is editable by the person it describes. Your correction replaces the machine output and is the version used by the platform.
Prior exits and other track-record claims are self-reported until a human reviewer assesses the evidence you supplied. Until then they are labelled as pending.
6. Who can see what
A founder can see their own company and documents. Other founders cannot see them at all.
An investor can see a company summary only when the company is published, the founder has consented to sharing, and a match exists that passed every hard constraint.
Confidential documents additionally require the investor to be verified. Access checks run on our server and are enforced by database row-level security, not by hiding buttons.
Administrators can see verification queues, introduction oversight records and audit events in order to operate the platform.
7. Retention and deletion
You can unpublish at any time, which immediately stops new matching and investor visibility. You can withdraw a company, and you can delete it.
Deleting a company deletes its documents, extraction jobs, matches and shortlists. Audit events are retained without document content for operational integrity.
You can request deletion of your account and all associated records from the settings page.
8. Consent records
Acceptance of this policy and of the terms is stored with the policy key and version so we can show exactly which text you agreed to.
9. Contact
Privacy questions can be raised from the settings page inside your workspace. A published contact address will be added when the operating entity and jurisdiction are confirmed.
